Execution Evidence Protocol
The v2.4.0-rc.1 source candidate defines one layered path from enterprise-local private evidence through signed causal lifecycle records and ordered checkpoints to optional cryptographic transparency, independently authorized witnesses, policy-selected neutral tree-head anchors, deterministic offline verification, and a separately deployed enterprise-local semantic dispatch profile.
Strict readback and reconciliation are explicit and enterprise-operated. Factual truth, external authorization, legal identity, source independence, and complete observation remain outside automatic protocol conclusions.
Protocol components
| Component | Function |
|---|---|
| Receipt Evidence Node | Creates signed causal lifecycle records and strict reconciliation while private values remain enterprise-local. |
| Enterprise-local Semantic Dispatch Guardrail | Derives semantic identity internally, enforces durable lineage-lifetime uniqueness, and mediates a preconfigured enterprise adapter before any guarded callback. |
| Evidence Envelope v2 | Binds private events, signed attestations, stream continuity, ordered checkpoints, and evidence inclusion. |
| Hosted artifact gateway | Stores closed, signed public artifacts for durable retrieval; it is not a cryptographic transparency log. |
| Transparency operator | Appends signed checkpoints to an RFC 9162 Merkle history and issues signed, linked tree heads. |
| Witness and monitor | Verifies signed heads and consistency under exact authorization and retains accepted or conflicting views. |
| Neutral tree-head anchor | Periodically timestamps a policy-selected signed tree head; it does not anchor every receipt by default. |
| Independent layered verifier | Cross-binds supplied lifecycle, checkpoint, transparency, witness, anchor, finality, and readback artifacts offline. |
| Readback connector | Enterprise-operated source observation with committed reader and trust-domain identities. |
Enterprise-local semantic dispatch profile
The public protocol defines deterministic binding and classification semantics. Active mediation is a separate, enterprise-local guardrail; hosted ChoiceProof and public protocol surfaces never invoke external actions or custody adapter credentials.
Reservation and lineage
- Derive
Kinternally from enterprise scope and a stable operation lineage; deriveFfromK, the versioned normalization profile, action, normalized intent, and relevant configuration. - Enforce lifetime uniqueness of
(enterpriseScopeHash, K, F). A historicalFalways returns its stored operation. - Therefore
F1 → F2 → F1creates no new reservation, head advance, permit, or guarded callback. - An unseen
Fmay advance only from the exact current head at revisionn + 1, with a verified, closed supersession approval, after the predecessor resolves asCONFIRMED,NOT_APPLIED, orCONTRADICTED.UNRESOLVEDcannot advance the lineage.
Dispatch and recovery
- Durably commit pre-dispatch evidence before atomically consuming the single-use, fenced dispatch permit.
- Begin the preconfigured adapter callback only after that transaction commits.
- At or after permit consumption, recovery is readback-only. Callback failure, timeout, cancellation, or a missing report never makes the operation dispatchable again.
- Under the certified deployment assumptions, one semantic binding revision can cause at most one guarded adapter callback. That callback bound does not cover bypass credentials, incomplete normalization, or a non-atomic store. Preventing duplicate downstream effects additionally requires a one-dispatch or downstream-idempotency adapter boundary.
The semantic reference module remains evidence-only: it derives K when enterprise scope and stable-lineage inputs are supplied, validates F and binding hashes, and classifies supplied bindings, retries, conflicts, and declared supersessions. It does not authorize or prevent an action by itself.
Layered verifier result dimensions
The verifier reports thirteen independent dimensions. Each one is PASS, FAIL, INDETERMINATE, or NOT_PROVIDED with stable reason codes and explicit trust assumptions.
| Dimension | Evaluates | Result states |
|---|---|---|
| evidenceIntegrity | Schema, canonical hash, and artifact consistency. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| signerAuthenticity | Declared signing-key control under the selected signature domain. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| lifecycleCausalLinkage | Lifecycle transitions, parents, roots, and source-event identities. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| sequenceContinuity | Scoped stream, epoch, sequence, and predecessor continuity. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| checkpointInclusion | Evidence inclusion in the supplied ordered checkpoint. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| transparencyInclusion | Checkpoint entry inclusion in the signed RFC 9162 tree state. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| transparencyConsistency | Append-only extension between the supplied older and newer tree states. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| witnessMonitor | Authorized observations bound to one exact log, epoch, head, size, and root. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| equivocationDetection | Conflicting signed views available to the supplied observers. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| blockchainAnchor | Exact tree-head material at the selected chain, deployment, and contract. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| externalFinality | Separate provider and finality-policy evaluation. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| readback | Explicit observation from the enterprise-selected readback source. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
| reconciliation | Deterministic comparison of committed expected and observed results. | PASS · FAIL · INDETERMINATE · NOT_PROVIDED |
Execution Receipt creation
- Submit a declared attempt at the local ingress.
- Canonicalize and hash caller-defined private JSON locally.
- Create an Execution Receipt and signed Receipt Commitment.
- Append source-reported outcomes or reversals, or derive strict reconciliation from committed readback.
- Retain private values and credentials outside the receipt.
Layered reference verification
- Supply the enterprise-held Receipt Bundle or evidence closure.
- Recompute lifecycle, signatures, checkpoints, and inclusion.
- Verify optional transparency consistency, witness context, tree-head anchor, and finality artifacts.
- Evaluate readback, reconciliation, and factual-truth scope as separate results.
Commitment construction
commitment = sha256(domain || canonicalize(privateValue))
Private caller-defined values are hashed at local ingress and are not included in the Execution Receipt or Receipt Bundle.
Verification scope
Core layered verification performs no hidden network request and does not depend on a ChoiceProof hosted service, RPC provider, transparency service, or blockchain. Optional collectors and readback are separately selected and reported.
Factual truth remains NOT_DETERMINED_BY_PROTOCOL. Deployment assurance depends on controls in the target environment; source distribution does not establish target-environment assurance.